09-11-2018 08:22 AM - edited 02-21-2020 08:13 AM
Hello,
I'm working on Analysis Intrusion Events on FMC.
I notice that a message "Internal_Event_Session_Add" is always there which shows TCP connection detected with many many counts.
After checking my IPS Policy, it said this rule is disabled. I don't understand why I still get this message.
I'd like to delete this message because it is a false alert.
Could someone show me how to do?
Thanks.
09-12-2018 04:10 AM
09-12-2018 06:22 AM
I have already tried this. The message is always there, it only resets the counter.
Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide